Page 1 of 1
CDM Assessment
20 quick questions on your security maturity. Rate each on a 0–4 scale: 0 = Not in place · 1 = Ad hoc · 2 = Partial · 3 = Mostly · 4 = Fully / optimized.
About you & your organization
First name
*
Last name
*
Company name
*
Business email
*
Phone
Website
Company size
*
Organization type
*
Primary pain point
*
Compliance need
*
Identify
Devices: comprehensive, up-to-date inventory of all hardware (workstations, servers, mobile, IoT, BYOD)
*
Devices: comprehensive, up-to-date inventory of all hardware (workstations, servers, mobile, IoT, BYOD)
0
1
2
3
4
Not in place
Fully / optimized
Applications: maturity of inventorying all software/applications (versions, data flows, dependencies)
*
Applications: maturity of inventorying all software/applications (versions, data flows, dependencies)
0
1
2
3
4
Not in place
Fully / optimized
Networks: extent authorized network communication paths and data flows are mapped, baselined, visualized
*
Networks: extent authorized network communication paths and data flows are mapped, baselined, visualized
0
1
2
3
4
Not in place
Fully / optimized
Data: completeness/accuracy of inventorying, classifying, and prioritizing sensitive data across all locations
*
Data: completeness/accuracy of inventorying, classifying, and prioritizing sensitive data across all locations
0
1
2
3
4
Not in place
Fully / optimized
Users: authoritative directory of all user identities (roles, access levels, privileges)
*
Users: authoritative directory of all user identities (roles, access levels, privileges)
0
1
2
3
4
Not in place
Fully / optimized
Protect
Devices: consistency of preventative controls (hardening, patching, EDR) across managed devices
*
Devices: consistency of preventative controls (hardening, patching, EDR) across managed devices
0
1
2
3
4
Not in place
Fully / optimized
Applications: maturity of application safeguards (secure SDLC, WAF, RASP)
*
Applications: maturity of application safeguards (secure SDLC, WAF, RASP)
0
1
2
3
4
Not in place
Fully / optimized
Networks: use of segmentation, micro-segmentation, and Zero Trust to limit unauthorized comms and contain breaches
*
Networks: use of segmentation, micro-segmentation, and Zero Trust to limit unauthorized comms and contain breaches
0
1
2
3
4
Not in place
Fully / optimized
Data: effectiveness of technical controls (encryption, DLP) protecting sensitive data
*
Data: effectiveness of technical controls (encryption, DLP) protecting sensitive data
0
1
2
3
4
Not in place
Fully / optimized
Users: effectiveness of awareness training and identity policies (MFA, least privilege) in reducing human risk
*
Users: effectiveness of awareness training and identity policies (MFA, least privilege) in reducing human risk
0
1
2
3
4
Not in place
Fully / optimized
Detect
Devices: use of continuous monitoring (EDR) to detect anomalies and indicators of compromise on devices
*
Devices: use of continuous monitoring (EDR) to detect anomalies and indicators of compromise on devices
0
1
2
3
4
Not in place
Fully / optimized
Applications: how effectively application logs and events are correlated/analyzed (SIEM) to detect anomalous behavior
*
Applications: how effectively application logs and events are correlated/analyzed (SIEM) to detect anomalous behavior
0
1
2
3
4
Not in place
Fully / optimized
Networks: capability to monitor traffic for anomalies and hunt intrusions (NDR/IDS)
*
Networks: capability to monitor traffic for anomalies and hunt intrusions (NDR/IDS)
0
1
2
3
4
Not in place
Fully / optimized
Data: maturity of detecting data breaches (access-log analysis, unusual movement, provenance)
*
Data: maturity of detecting data breaches (access-log analysis, unusual movement, provenance)
0
1
2
3
4
Not in place
Fully / optimized
Users: use of UEBA or similar to detect anomalous user behavior, compromised credentials, insider threats
*
Users: use of UEBA or similar to detect anomalous user behavior, compromised credentials, insider threats
0
1
2
3
4
Not in place
Fully / optimized
Respond & Recover
Devices: maturity and tested effectiveness of responding to a compromised device (containment, eradication, clean restore)
*
Devices: maturity and tested effectiveness of responding to a compromised device (containment, eradication, clean restore)
0
1
2
3
4
Not in place
Fully / optimized
Applications: preparedness to respond to a compromised application (isolate, assess, recover with minimal interruption)
*
Applications: preparedness to respond to a compromised application (isolate, assess, recover with minimal interruption)
0
1
2
3
4
Not in place
Fully / optimized
Networks: how well-defined and rehearsed the incident-response plan is for a network intrusion
*
Networks: how well-defined and rehearsed the incident-response plan is for a network intrusion
0
1
2
3
4
Not in place
Fully / optimized
Data: ability to respond to and recover from a data breach (damage assessment, integrity restore, stakeholder comms)
*
Data: ability to respond to and recover from a data breach (damage assessment, integrity restore, stakeholder comms)
0
1
2
3
4
Not in place
Fully / optimized
Users: preparedness to respond to a compromised account or insider threat (revocation, investigation, recovery)
*
Users: preparedness to respond to a compromised account or insider threat (revocation, investigation, recovery)
0
1
2
3
4
Not in place
Fully / optimized
Submit